Threat reportMalwareTL-2026-1995

WindRelay + SpyNote Combo: NFC Relay Malware Enables Contactless Card Fraud Across Central/Eastern Europe

highACTIVE

WindRelay + SpyNote Combo (TL-2026-1995), also tracked as WindRelay NFC Relay Combo, is a high-severity malware campaign, first published 2026-08-12. It has no confirmed attribution, affects Google Android, maps to 12 MITRE ATT&CK techniques (T1407, T1417, T1418), and is covered by 9 detection rules and 21 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
12MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-1995

Threat ID
TL-2026-1995
Also known as
WindRelay NFC Relay Combo, WindRelay/SpyNote fraud scheme
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
finance, banking
Target regions
czechia, slovakia, slovenia, poland, Central Europe, 151 - Eastern Europe
Detection rules
9
Indicators of compromise
21

Malware and tooling in WindRelay + SpyNote Combo

Malware and tooling: SpyNote, WindRelay

How WindRelay + SpyNote Combo works

Group-IB documents WindRelay, a newly tracked purpose-built Android NFC relay tool, deployed alongside the SpyNote RAT in a vishing-driven fraud scheme. Fraudsters posing as bank employees talk victims into sideloading a personalized SpyNote APK, then abuse its Accessibility Service access to silently install WindRelay, which relays live contactless card data to attacker-controlled devices for card-present purchases and ATM cash-outs, alongside fraudulent digital loans issued via banking-app takeover.

Group-IB's Fraud Protection team documented a two-malware Android fraud combo active across Central and Eastern Europe since at least November 2025. The scheme begins with a phone call in which the fraudster impersonates a bank employee and claims a problem with the victim's card, then walks the victim through installing an Android APK during the live call. That first-stage app is a personalized variant of the SpyNote RAT — the application label is set to the victim's own name, a deliberate trust-abuse tactic intended to lower suspicion since victims believe they are installing something sanctioned by their bank. SpyNote requests Accessibility Service permission, which it then abuses to silently sideload a second payload, WindRelay, via the device's package installer without triggering a visible screen-share prompt or requiring further victim interaction. WindRelay is Group-IB's newly tracked name for a purpose-built NFC relay tool: once installed, it instructs the victim (still on the phone with the fraudster) to tap their physical contactless payment card to their own handset and enter their PIN. WindRelay reads the live EMV contactless handshake off the NFC chip and streams it in real time over the internet to a second, attacker-controlled Android device, which replays the exchange at a real merchant POS terminal or ATM as if the victim's card were physically present, PIN included. In parallel, SpyNote's remote-control and Accessibility Service access is used to navigate the victim's mobile banking app and issue a fraudulent digital loan in the victim's name — a second monetization path pursued in the same call. Group-IB reports the entire sequence, from the first malicious install through the NFC capture and loan issuance, completes in as little as 13 minutes, well inside the window in which a victim could contact their bank to intervene. The operation has hit victims across Czechia, Slovakia, Slovenia, and Poland; Group-IB attributes the campaign via metadata correlation across 23 WindRelay and 7 SpyNote samples collected between November 2025 and July 2026, alongside 4 shared C2 IP addresses. Group-IB frames the technique as part of a broader, fast-growing NFC relay threat class: Kaspersky separately reported a 188% year-over-year increase in NFC-relay-style Android malware detections (35,600 blocked attacks January-April 2026 versus over 12,300 in the same period of 2025, across families including SuperCard X, PhantomCard, NGate, and modified NFCGate variants), and Group-IB's own prior research on 'Ghost Tap'/TX-NFC-style HCE card-emulation fraud documents a related but architecturally distinct NFC abuse pattern (relay app runs on the fraudster's device using stolen card credentials rather than live-relaying from the victim's phone) that has produced at least $355,000 in documented losses from a single point-of-sale vendor between November 2024 and August 2025.

MITRE ATT&CK techniques used in TL-2026-1995

Defense Evasion

T1407 Download New Code at Runtime

Collection

T1417 Input Capture; T1453 Abuse Accessibility Features; T1636.003 Contact List; T1638 Adversary-in-the-Middle

Discovery

T1418 Software Discovery

Impact

T1516 Input Injection; T1657 Financial Theft

Persistence

T1624.001 Broadcast Receivers

Exfiltration

T1646 Exfiltration Over C2 Channel

Initial Access

T1660 Phishing

Command and Control

T1663 Remote Access Software

Affected products and versions in WindRelay + SpyNote Combo

  • Google — Android
    Vulnerable versions: Android devices with sideloading/unknown-sources install enabled

Remediation for WindRelay + SpyNote Combo

Immediate actions

  • Block outbound traffic to the 4 confirmed WindRelay C2 IPs at network/perimeter controls
  • Push mobile threat defense / EDR signatures for the 23 WindRelay and 7 SpyNote sample hashes
  • Alert bank fraud teams to correlate closely-timed digital loan requests with same-session card-present transactions
  • Deploy out-of-band (SMS/app push) confirmation for any high-risk digital lending action initiated during or immediately after a phone call

Workarounds

  • Disable 'install unknown apps' / sideloading permission on Android devices for non-technical users where feasible via MDM
  • Restrict Accessibility Service grants to known, vetted applications via enterprise mobility management policy

Longer-term hardening

  • Mobile threat defense (MTD) monitoring for apps requesting the NFC + Accessibility Service + INTERNET permission combination together
  • Detect and flag Android package installs triggered from within an active phone call session (behavioral telemetry)
  • Bank-side anomaly detection for card-present transactions occurring within minutes of a digital loan issuance on the same account
  • Customer education campaigns explicitly warning that banks never ask customers to install an app or tap their card to their own phone during a call

Timeline of WindRelay + SpyNote Combo

  • NFC relay attacks first documented against Czech Republic victims, predating the WindRelay/SpyNote combo, per Group-IB's prior threat tracking.
  • Arrest made in Prague tied to earlier NFC relay fraud activity, referenced by Group-IB as prior regional context for the current campaign.
  • Earliest WindRelay samples in Group-IB's 23-sample set date from November 2025, marking the start of the tracked campaign window.
  • Group-IB publishes 'Ghost Tapped: Tracking the Rise of Chinese Tap-to-pay Android Malware,' documenting the related but distinct TX-NFC/Ghost Tap HCE-based relay fraud pattern.
  • Kaspersky publicly reports a 188% year-over-year surge in NFC-relay-style Android malware detections for January-April 2026 (35,600 blocked attacks vs. 12,300+ in the same 2025 period), corroborating the growth of this technique class.
  • Most recent WindRelay samples in Group-IB's dataset date from July 2026, indicating the campaign remained active through mid-2026.
  • Trade press (GBHackers, Cybersecurity News) republish technical summaries of the Group-IB disclosure the same day, reiterating the 13-minute attack timeline and IOC counts.
  • Group-IB publishes 'Gone with the WindRelay,' publicly disclosing the WindRelay NFC relay tool, its pairing with SpyNote, the 13-minute attack chain, victimology across Czechia, Slovakia, Slovenia and Poland, and full IOC set (4 C2 IPs, 23 WindRelay + 7 SpyNote SHA1 hashes).

Sources cited for WindRelay + SpyNote Combo

Detection coverage for TL-2026-1995

As of 2026-08-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1995 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats